Verified today
Contractor GRC AC (Access Control) Professional
About the role
YASH Technologies is hiring a Contractor GRC AC (Access Control) Professional in Hyderabad, TG, IN to support SAP security and compliance initiatives. The role involves hands-on configuration and maintenance of SAP GRC Access Control (10.x/12.0) and SAP ECC Security, including role design, emergency access management, MSMP workflows, BRF+ rules, and SoD ruleset customization. Day-to-day work covers troubleshooting authorization errors, designing mitigation controls, mapping controls to SOX/ITGC requirements, generating audit-ready reports, and leading client workshops while guiding junior consultants. The position requires 8–10 years of hands-on expertise and includes end-to-end implementation support from blueprinting through hypercare.
What you’ll do
- Configure Emergency Access Management (Firefighter) for ECC landscapes, including ID-based vs. Role-based setups and Log Review workflows
- Configure MSMP workflows and BRF+ rules for complex access approval processes (ARM)
- Customize SoD Rulesets for both ECC (T-Code based) and S/4HANA environments
- Design Mitigation Controls and manage the mitigation assignment lifecycle for unavoidable risks
- Map GRC controls to SOX/ITGC requirements and generate audit-ready compliance reports for ECC systems
- Handle GRC background jobs, synchronization issues, and system connector setups between GRC and ECC
- Lead client workshops, gather requirements, and guide junior consultants
- Manage full end-to-end implementations from Blueprinting to Hypercare support
What you’ll bring
- 8–10 years of hands-on expertise in SAP GRC Access Control (10.x/12.0) and SAP ECC Security
- Expert in building and maintaining Single, Composite, and Derived roles in SAP ECC using transaction PFCG
- Proficient in complex user administration (SU01, SU10) and troubleshooting authorization errors using SU53 and ST01/STAUTHTRACE
- Expert in configuring Emergency Access Management (Firefighter) for ECC landscapes, including ID-based vs. Role-based setups and Log Review workflows
- Strong ability to configure MSMP workflows and BRF+ rules for complex access approval processes (ARM)
- Experience in customizing SoD Rulesets for both ECC (T-Code based) and S/4HANA environments
- Proficiency in designing Mitigation Controls and managing the mitigation assignment lifecycle for unavoidable risks
- Experience handling security upgrades and role adjustments